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AMENDMENTS TO THE CLAIMS: 

This listing of claims will replace all prior versions, and listings, of claims in the 
application: 

1-6. (Cancelled) 

7. (Currently Amended) A computer program product for controlling a computer to detect 
malware, said computer program product comprising: 

file access request receiving logic operable to receive at an assessment computer a file 
access clearance request from a requesting computer, said file access clearance request including 
data identifying a computer file to be accessed by said requesting computer; 

file access clearance response generating logic operable in dependence upon said data 
identifying said computer file to determine if said computer file has previously been assessed as 
not containing malware and to generate a file access clearance response; and 

file access clearance response transmitting logic operable to transmit said file access 
clearance response to said requesting computer; 

whe.re.in said assessment mmnuter store * a database of computer files and said database 
includes for eac h com puter file a persistence flag i n d i cati ng wh ether an entry relating to said 
com puter file should be purged from said da t a b ase during purge operations . 

8. (Original) A computer program product as claimed in claim 7, wherein said data 
identifying said computer file includes a checksum value calculated from said computer file. 
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9. (Original) A computer program product as claimed in claim 7, wherein said data 
identifying said computer file includes one or more of a filename of said computer file, data 
identifying said requesting computer and a storage location of said computer file. 

10. (Original) A computer program product as claimed in claim 7, wherein if said file 
access clearance response indicates a scan of said computer file is required by said assessment 
computer, then computer file receiving logic is operable to receive at said assessment computer 
said computer file from said requesting computer and performing a malware scan of said 
computer file. 

11. (Original) A computer program product as claimed in claim 7, wherein if said file 
access clearance response indicates access to said computer file is denied, then triggering a 
denied access response in said assessment computer. 

12. (Currently Amended) A computer program product as claimed in claim 7, wherein 
said assessment computer stores a database of computer files previously assessed as to specifjes 
whether riwre.s pective computer files contain malware. 

13. (Currently Amended) A computer program product as claimed in claim 12, wherein 
said database includes for each computer file fields specifying one or more of a filename of said 
computer file, data identifying said requesting computer and a storage location of said computer 
file, a checksum value calculated from said computer ftler^fneandan access flag indicating 
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whether access to said computer file is denie d and a P uuUli i ll fl afl i n dicti ng whothor entries 
it Uing to said computer file ohould b t pu r ged from -n id databaoo during purge operations . 

14. (Original) A computer program product as claimed in claim 7, wherein said 
assessment computer is operable in at least a higher level security mode and a lower level 
security mode, said assessment computer serving to deny access to greater range of computer 
files when operating in said higher level security mode compared with said lower level security 
mode. 

15. (Original) A computer program product as claimed in claim 14, wherein said 
assessment computer is triggered to change from said lower level security mode to said higher 
level security mode by a lock down trigger message received at said assessment computer from a 
remote computer. 

16. (Original) A computer program product as claimed in claim 7, wherein a plurality of 
requesting computers share access to an assessment computer for determining whether file 
access requests by those requesting computers should be denied. 

17. (Currently Amended) A computer program product for controlling a computer to 
detect malware, said computer program product comprising: 

file access request detecting logic operable to detect a file access request to a computer 
file by a requesting computer; 
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file access clearance request generating logic operable to generate a file access clearance 
request including data identifying said computer file; 

file access clearance request transmitting logic operable to transmrt said file access 
clearance request from said requesting computer to an assessment computer responsible for 
assessment of whether said computer file contains malware; 

file access clearance request receiving logic operable to receive at said assessment 
computer said file access clearance request from a requesting computer; 

file access clearance response generating logic operable in dependence upon said data 
identifying rid computer file to determine if said computer file has previously been assessed as 
not containing malware and to generate a file access clearance response; 

file access clearance response transmitting logic operable to transmit said file access 
clearance response to said requesting computer; 

file access clearance response receiving logic operable to receive at said requesting 
computer said file access clearance response from said assessment computer; and 

file access permitting logic operable if said file access clearance response indicates said 
computer file does not contain malware to permit said file access request by said requesting 
computer! 

... hrr ^ . ai „ ...^t ,nmnuter store* , database, of computer files and said database 
in£Mg ^^ fhr indicatin g whether an entry relating to said 

am pler file sh""" he. nureed from said dat abase during purge ojemtions. 

18. (Original) A computer program product as claimed in claim 17, wherein said data 
identifying said computer file includes a checksum value calculated from said computer file. 



-6- 



942314 



HINCHLIFFE et al. 
Appl. No. 09/912,392 
April 7, 2005 



19. (Original) A computer program product as claimed in claim 17, wherein said data 
identifying said computer file includes one or more of a filename of said computer file, data 
identifying said requesting computer and a storage location of said computer file. 

20. (Original) A computer program product as claimed in claim 17, wherein if said file 
access clearance response indicates a scan of said computer file is required by said assessment 
computer, then computer file transmitting logic is operable to transmit said computer file from 
said requesting computer to said assessment computer, receiving at said assessment computer 
said computer file from said requesting computer and performing a malware scan of said 
computer file. 

21. (Original) A computer program product as claimed in claim 17, wherein if said file 
access clearance response indicates access to said computer file is denied, then triggering a 
denied access response in said assessment computer. 

22. (Original) A computer program product as claimed in claim 17, wherein if said file 
access clearance response indicates access to said computer file is denied, then triggering a 
denied access response in said requesting computer. 

23. (Currently Amended) A computer program product as claimed in claim 17, 
wherein said q^mu.t computnr r tnm n database of computer files p.^ ioualy aoooGoed no t o 
nrWVw thays pftcifies whethe r res pective computer files contain malware. 
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24. (Currently Amended) A computer program product as claimed in claim 23, wherein 
said database includes for each computer file fields specifying one or more of a filename of said 
computer file, data identifying said requesting computer and a storage location of said computer 
file, a checksum value calculated from said computer fiter^a nfile and an access flag indicating 
whether access to said computer file is denied and a p e rsist e nc e flag indicating wh e ther entri e s 
relating to said computer file should b e purg e d from said databas e during purge operations . 

25. (Original) A computer program product as claimed in claim 17, wherein said 
assessment computer is operable in at least a higher level security mode and a lower level 
security mode, said assessment computer serving to deny access to greater range of computer 
files when operating in said higher level security mode compared with said lower level security 
mode. 

26. (Original) A computer program product as claimed in claim 25, wherein said 
assessment computer is triggered to change from said lower level security mode to said higher 
level security mode by a lock down trigger message received at said assessment computer from a 
remote computer. 

£827. ( Currently Amended) A computer program product as claimed in claim 17, wherein 
a plurality of requesting computers share access to an assessment computer for determining 
whether file access requests by those requesting computers should be denied. 
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29-34. (Cancelled) 

3534. (Currently Amended) A method of detecting malware, said method comprising the 
steps of: 

receiving at an assessment computer a file access clearance request from a requesting 
computer, said file access clearance request including data identifying a computer file to be 
accessed by said requesting computer; 

in dependence upon said data identifying said computer file determining if said computer 
file has previously been assessed as not containing malware and generating a file access 
clearance response; and 

transmitting said file access clearance response to said requesting computer; 

wherein said assessment computer stores a database of computer files and said database 
includes for each computer file a persistence flag indicating whether an entry relating to said 
computer file should be purged from said database during purge operations . 

3635. ( Currently Amended) A method as claimed in claim 3534, wherein said data 
identifying said computer file includes a checksum value calculated from said computer file. 

3236. (Currently Amended) A method as claimed in claim 3534, wherein said data 
identifying said computer file includes one or more of a filename of said computer file, data 
identifying said requesting computer and a storage location of said computer file. 



-9- 



942314 



HINCHLIFFE et al. 
AppL No. 09/912,392 
April 7, 2005 

3&37. (Currently Amended) A method as claimed in claim 3534, wherein if said file 
access clearance response indicates a scan of said computer file is required by said assessment 
computer, then receiving at said assessment computer said computer file from said requesting 
computer and performing a malware scan of said computer file. 

3938. ( Currently Amended) A method as claimed in claim 3534, wherein if said file 
access clearance response indicates access to said computer file is denied, then triggering a 
denied access response in said assessment computer. 

4039. (Currently Amended) A method as claimed in claim 3534, wherein said assessment 
comput e r stores a database of computer files previou s ly assessed as to wheth e r they specifies 
whether respective computer files contain malware. 

4140. (Currently Amended) A method as claimed in claim 4039, wherein said database 
includes for each computer file fields specifying one or more of a filename of said computer file, 
data identifying said requesting computer and a storage location of said computer file, a 
checksum value calculated from said computer fiter-an file and an access flag indicating whether 
access to said computer file is denie d and a persistence flag indicating whether entries relating to 
said computer fil e should be purg e d from said databas e during purge operations . 

4341. ( Currently Amended) A method as claimed in claim 3534, wherein said assessment 
computer is operable in at least a higher level security mode and a lower level security mode, 
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said assessment computer serving to deny access to greater range of computer files when 
operating in said higher level security mode compared with said lower level security mode. 

4342. (Currently Amended) A method as claimed in claim 5541, wherein said assessment 
computer is triggered to change from said lower level security mode to said higher level security 
mode by a lock down trigger message received at said assessment computer from a remote 
computer. 

[[44]]43. (Currently Amended) A method as claimed in claim 3§34, wherein a plurality of 
requesting computers share access to an assessment computer for determining whether file 
access requests by those requesting computers should be denied. 

4544. (Currently Amended) A method of detecting malware, said method comprising the 
steps of: 

detecting a file access request to a computer file by a requesting computer; 

generating a file access clearance request including data identifying said computer file; 

transmitting said file access clearance request from said requesting computer to an 
assessment computer responsible for assessment of whether said computer file contains malware; 

receiving at said assessment computer said file access clearance request from a requesting 
computer; 

in dependence upon said data identifying said computer file determining if said computer 
file has previously been assessed as not containing malware and generating a file access 
clearance response; 
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transmitting said file access clearance response to said requesting computer; 

receiving at said requesting computer said file access clearance response from said 
assessment computer; and 

if said file access clearance response indicates said computer file does not contain 
malware, then permitting said file access request by said requesting computer; 

wherein said assessment computer stores a database of computer files and said database 
includes for each computer file a persistence flag indicating whether an entry relating to said 
computer file should be purged from said database during purge operations . 

4645. ( Currently Amended) A method as claimed in claim 4544, wherein said data 
identifying said computer file includes a checksum value calculated from said computer file. 

4346. ( Currently Amended) A method as claimed in claim 4544, wherein said data 
identifying said computer file includes one or more of a filename of said computer file, data 
identifying said requesting computer and a storage location of said computer file. 

4847. (Currently Amended) A method as claimed in claim 4544, wherein if said file 
access clearance response indicates a scan of said computer file is required by said assessment 
computer, then transmitting said computer file from said requesting computer to said assessment 
computer, receiving at said assessment computer said computer file from said requesting 
computer and performing a malware scan of said computer file. 
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4948. (Currently Amended) A method as claimed in claim 4544, wherein if said file 
access clearance response indicates access to said computer file is denied, then triggering a 
denied access response in said assessment computer. 

5049. ( Currently Amended) A method as claimed in claim 4544, wherein if said file 
access clearance response indicates access to said computer file is denied, then triggering a 
denied access response in said requesting computer. 

54-50. (Currently Amended) A method as claimed in claim 4544, wherein said assessm e nt 
comput e r stores a database of computer files specifies whether respective computer 
files previously assessed as to wh e ther they contain malware. 

5251. (Currently Amended) A method as claimed in claim 5450, wherein said database 
includes for each computer file fields specifying one or more of a filename of said computer file, 
data identifying said requesting computer and a storage location of said computer file, a 
checksum value calculated from said computer fiter-a nfile and an access flag indicating whether 
access to said computer file is denied and a p e rsistence flag indicating whether e ntries relating to 
said computer fil e should be purged from said database during purg e operations . 

5352. ( Currently Amended) A method as claimed in claim 4544, wherein said assessment 
computer is operable in at least a higher level security mode and a lower level security mode, 
said assessment computer serving to deny access to greater range of computer files when 
operating in said higher level security mode compared with said lower level security mode. 
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5453. (Currently Amended) A method as claimed in claim 5552, wherein said assessment 
computer is triggered to change from said lower level security mode to said higher level security 
mode by a lock down trigger message received at said assessment computer from a remote 
computer. 

5554. ( Currently Amended) A method as claimed in claim 4544, wherein a plurality of 
requesting computers share access to an assessment computer for determining whether file 
access requests by those requesting computers should be denied. 

56-61. (Cancelled) 

6261. ( Currently Amended) Apparatus for controlling a computer to detect malware, said 
apparatus comprising: 

a file access request receiver operable to receive at an assessment computer a file access 
clearance request from a requesting computer, said file access clearance request including data 
identifying a computer file to be accessed by said requesting computer; 

a file access clearance response generator operable in dependence upon said data 
identifying said computer file to determine if said computer file has previously been assessed as 
not containing malware and to generate a file access clearance response; and 

a file access clearance response transmitter operable to transmit said file access clearance 
response to said requesting computer^ 
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wherein said assessment computer stores a database of computer files and said database 
includes for each computer file a persistence flag indicating whether an entry relating to said 
computer file should be purged from said database during purge operations . 

6362. (Currently Amended) Apparatus as claimed in claim 6361, wherein said data 
identifying said computer file includes a checksum value calculated from said computer file. 

6463. (Currently Amended) Apparatus as claimed in claim 6361, wherein said data 
identifying said computer file includes one or more of a filename of said computer file, data 
identifying said requesting computer and a storage location of said computer file. 

6564. Apparatus as claimed in claim 6361, wherein if said file access clearance response 
indicates a scan of said computer file is required by said assessment computer, then a computer 
file receiver is operable to receive at said assessment computer said computer file from said 
requesting computer and performing a malware scan of said computer file. 

6665. (Currently Amended) Apparatus as claimed in claim 6361, wherein if said file 
access clearance response indicates access to said computer file is denied, then triggering a 
denied access response in said assessment computer. 

6766. ( Currently Amended) Apparatus as claimed in claim 6361, wherein said ass e ssment 
comput e r stores a database of computer files previously assessed as to whether tho y specifies 
whether respective computer files contain malware. 
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6867. (Currently Amended) Apparatus as claimed in claim 6266, wherein said database 
includes for each computer file fields specifying one or more of a filename of said computer file, 
data identifying said requesting computer and a storage location of said computer file, a 
checksum value calculated from said computer fife^-aft file and an access flag indicating whether 
access to said computer file is denied and a persistence flag indicating whether e ntries relating to 
said computer file should be purg e d from said database during purge operations . 

6968. (Currently Amended) Apparatus as claimed in claim 6361, wherein said assessment 
computer is operable in at least a higher level security mode and a lower level security mode, 
said assessment computer serving to deny access to greater range of computer files when 
operating in said higher level security mode compared with said lower level security mode. 

7069. (Currently Amended) Apparatus as claimed in claim 6968, wherein said assessment 
computer is triggered to change from said lower level security mode to said higher level security 
mode by a lock down trigger message received at said assessment computer from a remote 
computer. 

74-70. ( Currently Amended) Apparatus as claimed in claim 6261, wherein a plurality of 
requesting computers share access to an assessment computer for determining whether file 
access requests by those requesting computers should be denied. 
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3271. (Currently Amended) Apparatus for controlling a computer to detect malware, said 
apparatus comprising: 

a file access request detector operable to detect a file access request to a computer file by 
a requesting computer; 

a file access clearance request generator operable to generate a file access clearance 
request including data identifying said computer file; 

a file access clearance request transmitter operable to transmit said file access clearance 
request from said requesting computer to an assessment computer responsible for assessment of 
whether said computer file contains malware; 

a file access clearance request receiver operable to receive at said assessment computer 
said file access clearance request from a requesting computer; 

a file access clearance response generator operable in dependence upon said data 
identifying said computer file to determine if said computer file has previously been assessed as 
not containing malware and to generate a file access clearance response; 

a file access clearance response transmitter operable to transmit said file access clearance 
response to said requesting computer; 

a file access clearance response receiver operable to receive at said requesting computer 
said file access clearance response from said assessment computer; and 

a file access permission unit operable if said file access clearance response indicates said 
computer file does not contain malware to permit said file access request by said requesting 
computer^ 
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wherein said assessment computer stores a database of computer files and said database 
includes for each computer file a persistence flag indicating whether an entry relating to said 
computer file should be purged from said database during purge operations . 

7372. ( Currently Amended) Apparatus as claimed in claim 7371, wherein said data 
identifying said computer file includes a checksum value calculated from said computer file. 

7473. (Currently Amended) Apparatus as claimed in claim 7371, wherein said data 
identifying said computer file includes one or more of a filename of said computer file, data 
identifying said requesting computer and a storage location of said computer file. 

7574. (Currently Amended) Apparatus as claimed in claim 7371, wherein if said file 
access clearance response indicates a scan of said computer file is required by said assessment 
computer, then a computer file transmitter is operable to transmit said computer file from said 
requesting computer to said assessment computer, receiving at said assessment computer said 
computer file from said requesting computer and performing a malware scan of said computer 
file. 

7675. ( Currently Amended) Apparatus as claimed in claim 7371, wherein if said file 
access clearance response indicates access to said computer file is denied, then triggering a 
denied access response in said assessment computer. 
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7776. ( Currently Amended) Apparatus as claimed in claim 7371, wherein if said file 
access clearance response indicates access to said computer file is denied, then triggering a 
denied access response in said requesting computer. 

7877. ( Currently Amended) Apparatus as claimed in claim 7371, wherein said assessment 
comput e r stores a database of computer files pr e viously ass e ssed as to whether they specifies 
whether respective computer files contain malware. 

7978. (Currently Amended) Apparatus as claimed in claim 7877, wherein said database 
includes for each computer file fields specifying one or more of a filename of said computer file, 
data identifying said requesting computer and a storage location of said computer file, a 
checksum value calculated from said computer fitepa ftfile and an access flag indicating whether 
access to said computer file is denie d and a p e rsist e nce flag indicating wh e ther entri e s relating to 
said computer fil e should be purged from said database during purge operations . 

8079. ( Currently Amended) Apparatus as claimed in claim 7371, wherein said assessment 
computer is operable in at least a higher level security mode and a lower level security mode, 
said assessment computer serving to deny access to greater range of computer files when 
operating in said higher level security mode compared with said lower level security mode. 

8J-80. ( Currently Amended) Apparatus as claimed in claim 8079, wherein said assessment 
computer is triggered to change from said lower level security mode to said higher level security 
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mode by a lock down trigger message received at said assessment computer from a remote 
computer. 

$281. (Currently Amended) Apparatus as claimed in claim 7271, wherein a plurality of 
requesting computers share access to an assessment computer for determining whether file 
access requests by those requesting computers should be denied., 
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